feat: reflect netOrk v0.4.1–v0.4.4 release notes and reconcile roadmap
CI / TypeScript — type-check (push) Failing after 10s
CI / Publish — build & push image (push) Has been skipped
CI / Deploy — pull & restart on host (push) Has been skipped

- Document the Web-SSH browser console and end-to-end RBAC enforcement
  (frontend gating added in v0.4.3), both previously missing from the
  feature list.
- Sync the roadmap with netOrk's docs/TODO.md: add Vault integration
  and the firewall-profile rework (top engineering priorities) and
  VLAN visualization.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Christian Manivong
2026-07-02 15:16:59 +02:00
co-authored by Claude Sonnet 5
parent b37703bbbb
commit 2a8a87bdd1
2 changed files with 30 additions and 0 deletions
+4
View File
@@ -94,6 +94,7 @@ const en = {
title: 'Device Management',
items: [
'CRUD for devices with credential profiles and SSH key management',
'Interactive Web-SSH console — full terminal session to any device straight from the browser, no separate SSH client needed',
'Per-device poll intervals (minutes) or manual-only',
'Status tracking: planned / staged / active / decommissioning / offline / disabled',
'Vendor / model / OS auto-populated from NAPALM get_facts()',
@@ -193,6 +194,7 @@ const en = {
'JWT authentication with remember-me (localStorage) or session-only (sessionStorage)',
'Two-factor authentication (MFA/TOTP): authenticator app at login, backup codes, session invalidation on TOTP changes, enforceable per role',
'RBAC with four built-in roles: viewer / operator / engineer / administrator',
'Permissions enforced end-to-end — nav, routes, and write actions are hidden in the UI to match the backend permission checks, not just disabled',
'Custom roles with any permission combination',
'Full audit log of all orchestration actions',
],
@@ -391,6 +393,7 @@ const de: Translations = {
title: 'Geräteverwaltung',
items: [
'CRUD für Geräte mit Credential-Profilen und SSH-Schlüsselverwaltung',
'Interaktive Web-SSH-Konsole — vollständige Terminal-Sitzung zu jedem Gerät direkt im Browser, kein separater SSH-Client nötig',
'Konfigurierbare Poll-Intervalle (Minuten) oder nur manuell',
'Statusverfolgung: geplant / bereitgestellt / aktiv / außer Betrieb / offline / deaktiviert',
'Hersteller / Modell / OS automatisch befüllt über NAPALM get_facts()',
@@ -490,6 +493,7 @@ const de: Translations = {
'JWT-Authentifizierung mit Remember-Me (localStorage) oder nur Sitzung (sessionStorage)',
'Zwei-Faktor-Authentifizierung (MFA/TOTP): Authenticator-App beim Login, Backup-Codes, Session-Invalidierung bei TOTP-Änderungen, pro Rolle erzwingbar',
'RBAC mit vier integrierten Rollen: Betrachter / Operator / Ingenieur / Administrator',
'Berechtigungen durchgängig erzwungen — Navigation, Routen und Schreibaktionen werden in der UI passend zu den Backend-Prüfungen ausgeblendet, nicht nur deaktiviert',
'Benutzerdefinierte Rollen mit beliebiger Berechtigungskombination',
'Vollständiges Audit-Log aller Orchestrierungsaktionen',
],